Red Hat Quay 3.2.1

CPE Details

Red Hat Quay 3.2.1
3.2.1
2021-06-04
13h32 +00:00
2021-06-04
13h35 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:redhat:quay:3.2.1:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

quay

Version

3.2.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-27832 2021-05-27 11h50 +00:00 A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
9
Critique
CVE-2020-27831 2021-05-26 21h46 +00:00 A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
4.3
Moyen
CVE-2020-14313 2020-08-11 11h42 +00:00 An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
4.3
Moyen